|
312571
|
8.1 |
HIGH
Network
|
logsign
|
unified_secops_platform
|
Logsign Unified SecOps Platform Directory data_export_delete_all Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected inst…
|
CWE-22
Path Traversal
|
CVE-2024-7601
|
2024-08-24 01:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312572
|
8.1 |
HIGH
Network
|
logsign
|
unified_secops_platform
|
Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Un…
|
CWE-22
Path Traversal
|
CVE-2024-7600
|
2024-08-24 01:35 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312573
|
9.8 |
CRITICAL
Network
|
youdiancms
|
youdiancms
|
A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulatio…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7329
|
2024-08-24 01:34 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312574
|
6.1 |
MEDIUM
Network
|
ckeditor
|
ckeditor
|
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in CKEditor 4 Code Snippet GeSHi plugin. The vulnerability allowed a reflected XSS …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43407
|
2024-08-24 01:20 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312575
|
6.5 |
MEDIUM
Network
|
okfn
|
ckan
|
CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext-archiver, that wor…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-43371
|
2024-08-24 01:20 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312576
|
- |
|
-
|
-
|
A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "passwo…
|
-
|
CVE-2024-42765
|
2024-08-24 01:18 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312577
|
- |
|
-
|
-
|
Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.
|
-
|
CVE-2024-42764
|
2024-08-24 01:18 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312578
|
- |
|
-
|
-
|
Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remot…
|
-
|
CVE-2024-37311
|
2024-08-24 01:18 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312579
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
usb: vhci-hcd: Do not drop references before new references are gained
At a few places the driver carries stale pointers
to refer…
|
-
|
CVE-2024-43883
|
2024-08-24 01:18 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312580
|
- |
|
-
|
-
|
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signature forgery where co…
|
-
|
CVE-2024-38807
|
2024-08-24 01:18 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|